Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

varx/tech

@varx@infosec.exchange
  • Open on infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm

This is the more tech-y alt of @varx@cybersecurity.theater

#nobot

0 Followers
0 Following
50 Posts
Joined October 25, 2017
pronouns:
he/they
languages:
📖 en, es; ✍️ en, ~es
that cavern thing I'm always nattering about:
https://codeberg.org/cavern/docs

Posts

Open post
varx
varx/tech @varx@infosec.exchange · 5d ago
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @varx@infosec.exchange
Here's the first puzzle, a warm-up. This is a recent heat map of memory usage in an HTTP service. What caused these four prominent "spurs" you see along the top? (More context, not all necessarily relevant: The service is running in Kubernetes, so the samples represent containers, each container running multiple workers. The Y axis, not shown, starts at zero. Time zone for X axis is unspecified.) Anything else can you figure out from this graph? #GraphMystery
1
1
0
0
Open post
varx
varx/tech @varx@infosec.exchange · 5d ago
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @varx@infosec.exchange
I likely won't be answering many questions about information not already in the posts. I'm using my discretion here as an experienced operator to determine which information my employer would consider sensitive—often that's "what does it do" and "what's the scale on that Y axis". I also mostly work with open source software, which makes this somewhat less fraught. I think it would be cool if other people post their own graphs to this hashtag, but... use your own judgement. Think about what you would feel comfortable sharing in a public bug report against a library. #GraphMystery
1
1
0
0
Open post
varx
varx/tech @varx@infosec.exchange · 5d ago
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Over the last 13 years as a software dev at SaaS companies, I've developed a fondness for graphs. I spend a lot of time staring at them to answer questions (mostly boiling down to "Why is the website sad?" and "Wait, *is* the site sad?") and I've learned to configure and read them quite well. But there are still many mysteries. I think it might be fun (and educational) to present a series of graphs with interesting patterns to see what other people think. Sometimes, I'll have my own answer. Sometimes I won't! I'm calling it #GraphMystery and I'll be posting them in this thread.
2
1
2
0
Open post
varx
varx/tech @varx@infosec.exchange · 5d ago
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @ysotomayor@mastodon.social
@ysotomayor@mastodon.social Looks like *someone* couldn't get through the day without Al! @rayckeith@techhub.social
0
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · 5d ago
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @bagder@mastodon.social
@bagder@mastodon.social I recently tried to cross-compile a small Rust program for Mac and discovered that in order to do so, I would have to sign some kind of developer agreement? Nope, don't feel like reading through all that. I can only imagine what it's like developing for Windows. Just compiling for Linux for now.
0
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Aug 07, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @lattera@bsd.network
@lattera@bsd.network (FYI this is a slop image -- there are a lot of tells, but the third panel is particularly egregious.)
0
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Aug 04, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @varx@infosec.exchange
@gaditb@icosahedron.website We got a solution! And I know what mathematical construct these decks match up to now. I still want to play around a bit more, but this has been a fun romp through algebra.
0
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Jul 31, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Great piece on how broken Pangram is: https://freddiedeboer.substack.com/p/i-wouldnt-say-pangram-is-broken-but (The author says "fragile" but no, it just looks broken to me.) TL;DR: Pangram gives inconsistent results for different excerpts of the same text, but almost always claims "100%" AI or human authorship for the whole document.
I Wouldn't Say Pangram is Broken, But I Would Say That It's Brittle
freddiedeboer.substack.com

I Wouldn't Say Pangram is Broken, But I Would Say That It's Brittle

it seems way too easy to provoke Pangram into contradicting its own results

1
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Jul 29, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @joshmillard@mastodon.social
@joshmillard@mastodon.social @emily@fedi.uni.horse I'm enjoying this juxtaposition.
2
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Jul 28, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to on icosahedron.website
@gaditb@icosahedron.website Yeah, it was inevitable that we would eventually come to an encoding that would allow representing most/all characters from world languages, unambiguously. The previous situation is untenable. However, I wonder if you would call the following "a unicode": A container format for text where there is a prefix indicating the character set (and maybe some delimiters, runlength indicators, whatever). A multi-lingual plaintext document would have different parts in different character sets.
0
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Jul 26, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @GuerillaOntologist@social.coop
@GuerillaOntologist@social.coop Oh, I didn't doubt that Starbucks would do something shitty! But thank you, that's a better source indeed (even if it's an aggravating format, but that's 2026 for you, I guess).
1
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Jul 25, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @GuerillaOntologist@social.coop
@GuerillaOntologist@social.coop Well... at least this site is honest about the text and images being AI-generated. I think I'd want to see some actual sources on this one, though.
0
1
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Jul 24, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @paco@infosec.exchange
@paco@infosec.exchange Oh, is *that* why Amtrak's login is always so flaky...
0
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Jul 24, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Doin' the old job hunt again. Hover or focus to reveal Sensitive
Company description: "Helping Medicare brokers build the insurance business of their dreams" ...wait, is that supposed to *entice* me? Or is it supposed to be satire?
0
1
2
0
Open post
varx
varx/tech @varx@infosec.exchange · Jul 19, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @jerry@infosec.exchange
@jerry@infosec.exchange Starting to feel a little warmer towards Kessler Syndrome.
0
1
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Jul 19, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @lattera@bsd.network
@lattera@bsd.network Reddit sure does have some types of guys.
0
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Jul 19, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @gewt@social.treehouse.systems
@gewt@social.treehouse.systems Naps are sacred.
0
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Jul 18, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Someone put a broken Zen clock out on the curb, and I'm pretty sure I can fix it wit some glue. (The solenoid broke off, probably due to the clock falling off something.) But I don't love the idea of having to deal with batteries. It takes 4 C-cell AA batteries. I wonder if I can just... wire the +5V/ground wires of a USB-A cord to the battery compartment contacts?!
0
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Jul 11, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @szbalint@mastodon.social

@szbalint@mastodon.social It's an interesting idea, but a few things to consider:

  • AC is expending on average, what, ~300W additional energy into the environment? If an AC and a set of awnings kept two identical houses at the same temperature, the AC would be strictly worse.

  • Houses exhibit the greenhouse effect. Solar energy that you bounce off the house may be re-radiated into space, while photons that enter the house are almost 100% converted to thermal energy.

  • ACs often bring houses below the no-AC ambient temperature, while shutters/awnings merely prevent houses from rising above it.

0
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Jul 09, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @varx@infosec.exchange
@gaditb@icosahedron.website After a couple of weeks of collaborating on this, my partner finally got a 55-card deck with 8 symbols per card! (I think I'm going to hold off on looking at the papers and slides, though. Still some stuff I want to ponder.)
1
1
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Jul 03, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @varx@infosec.exchange
Looks like Grid (https://mygrid.app/) is a pretty good candidate for a privacy-respecting location sharing app. Claims E2E-encryption, open source, minimal data collection (passkeys rather than email signin, own tileset rather than Google), de-Googled-compatible. Has a reasonable free tier. There are also some other "soft" signs of trustworthiness: Donation page, communicative devs. The encryption is via Matrix. (They let you specify your own homeserver, which sounds neat?) I'm pretty fed up with Matrix from both self-hosting and user perspectives, there are problems with the protocol and how it is managed, etc... but *how* Grid uses Matrix is probably more important than any of that. Might look into the details. I'm not set up for an audit of a phone app but at a glance this does look more promising than others!
3
0
1
0
Open post
varx
varx/tech @varx@infosec.exchange · Jun 29, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Any recommendations on an encrypted location-sharing app for smartphone? I'm looking for an app appropriate for someone to track the smartphone of a child or an adult in cognitive decline (with their consent!) but that doesn't leak geolocation info to the app provider and their 3672 closest vendors. So far I've found Paralino, which promises that it is e2e encrypted, but I haven't found an audit or anything. Has this one been audited? Recommendations for alternatives?
0
1
1
0
Open post
varx
varx/tech @varx@infosec.exchange · Jun 22, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @varx@infosec.exchange
@gaditb@icosahedron.website Oh man, this is even more interesting than I thought. I was pretty sure I had a solution, but I need to trim it down. (Being vague on purpose, will put any potential spoilers under CW.)
0
2
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Jun 22, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @gaditb@icosahedron.website
@gaditb@icosahedron.website Haha, nailed it! I'm glad to hear there's discussion of it but I'm going to keep bashing my head against this for now. (I should keep a list of all my failed attempts.)
0
1
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Jun 22, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @varx@infosec.exchange
Other people: "Looks simple enough, let's play!" Me: [staring into space, trying to visualize a 29-dimensional hypercube]
3
1
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Jun 22, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Dammit, I just realized that this card game is based on a clever math or information theory observation, and now I need to reverse engineer it to figure out how it works. ("What if you just played the g--" NO. Gotta understand it.)
2
1
1
0
Open post
varx
varx/tech @varx@infosec.exchange · May 26, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @technomancy@hey.hagelb.org
@technomancy@hey.hagelb.org For what it's worth, Kagi feels like less of an AI company than even DDG. It doesn't shove AI summaries in your face and the chatbot is entirely opt-in. But I acknowledge that the guy is at least a little bit sketchy. (I also currently find the Kagi search results better than Google's.)
0
1
0
0
Open post
varx
varx/tech @varx@infosec.exchange · May 17, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @jwrm22@hsnl.social
@jwrm22@hsnl.social @soph@grrl.me Maybe that's what the botlickers meant by "if you're not an early adopter you'll be left behind". 😆
0
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · May 12, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @ben@mastodon.lubar.me
@ben@mastodon.lubar.me @pikesley@mastodon.me.uk just going to do a little light colonization
0
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Apr 29, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @yosh@toot.yosh.is
@yosh ehhhh, each of the component services *also* has only one or two nines -- even if you ignore the dodgy aggregation function, it's not a good situation.
0
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Apr 28, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange

Quantum computing is going great:

https://github.com/GiancarloLelli/quantum/pull/1

The code submission that won 1 BTC for using a quantum computer to "crack" small ECC keys works exactly the same if you replace the quantum computer with /dev/urandom.

This isn't about brute-forcing a small key. It's the other way around: The quantum computer was being *used as* an RNG! 😆

4
0
1
0
Open post
varx
varx/tech @varx@infosec.exchange · Apr 21, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @dancingtreefrog@mastodon.social
@dancingtreefrog @SecureOwl Yeah, noreply had a blog up for a while with some of the catch, don't know if it's still there.
0
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Apr 20, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @haveibeenpwned@infosec.exchange
@haveibeenpwned Just this morning I got a phishing email to my Amtrak-specific email address. So the scammers are already on it. -.-
0
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Apr 19, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @RavenLuni@furry.engineer
@RavenLuni@furry.engineer @MongooseStudios@hachyderm.io It's... potentially non-contradictory. There is a small subset of devs who can use LLMs without deskilling or producing slop, and requiring people to *not* use AI in interviews might help identify that subset in the candidate pool. But obviously that further limits the candidate field in a way that's completely counterproductive when you consider the other constraints. (And yeah, I'm similarly reluctant to apply to any company that wants me to use LLMs.) @alexjsp@social.lol
0
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Apr 16, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange

@Skabber@hachyderm.io You're looking for a highly skilled person and requiring them to use The Deskilling Engine?

You may need to increase salary to compensate.

hachyderm.io

Jay Graves (@Skabber@hachyderm.io) - Hachyderm.io

0
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Apr 16, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange

@yama@tech.lgbt @badkeys@infosec.exchange Out of curiosity, what year are you posting from?

2
1
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Apr 15, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange

If cannabis is so great, why don't they sell cannater?

1
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Apr 03, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @troyhunt@infosec.exchange
@troyhunt@infosec.exchange Possible typo: In the unsmoothing section, is "6 fast requests" supposed to be "10 fast requests"? In any case, glad to see you're able to continue expanding what this service offers.
0
2
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Mar 24, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @evacide@hachyderm.io
@evacide@hachyderm.io I don't want to be secure, I just want to be right.
0
0
1
0
Open post
varx
varx/tech @varx@infosec.exchange · Mar 01, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @micahflee@infosec.exchange
@micahflee I'm very amused by all of the Bugcrowd garbage data that ended up in the DHS contractors table. Who knew that the Fortune 500 company `Phishing
2
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Feb 13, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @nolan@toot.cafe
@nolan@toot.cafe I was rather hoping to make it a bit less nebulous! Regardless of whether I should be impressed or not, I'd still be interested in a prediction if you'd like to make one.
0
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Feb 12, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @nolan@toot.cafe

@nolan@toot.cafe I'm not much into betting, but I wonder if you'd like to make a prediction.

What do you think is the probability that six months from now, you would be able to prompt an LLM to create a program with the following constraints?

  • Complexity on the order of IndexedDB
  • Not reimplementing something that already exists (I have several reasons for this constraint)
  • Accordingly, not driven off of a pre-existing test suite
  • High enough quality that you would risk your family's privacy and security on it
  • Maintainable code (either by human or further LLMs)
  • Takes at most a workday for prompting + manual fixups
  • API costs of at most $500

Or, how far out do you think it would be before this seems 90% likely to work?

(Feel free to quibble with any of my constraints. I chose those because that's what it would take to impress me.)

0
2
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Feb 12, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @jaredwhite@indieweb.social
@jaredwhite@indieweb.social @natanbc@mastodon.social We live in a time of miracles.
2
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Feb 08, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @nolan@toot.cafe

@nolan@toot.cafe I mean, I definitely think it can do an awful lot of jobs... badly. :-) The question for me is whether companies are actually OK with that reduction of quality. I'm concerned that they will be, at least in the short to medium term.

I do think that LLMs can often find vulns, and in the hands of an expert can assist in securing software. Otherwise it's just a flood of crap, as the article notes.

But coming back to my original question:

Is that code you generated usable?

  • Would you feel comfortable if your daily browser used this generated code instead of hand-written? Would you install it on your family's computers?
  • If no, what would it take for your answer to change?
2
4
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Feb 08, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @nolan@toot.cafe
@nolan@toot.cafe I can see companies successfully discarding reusability (as repugnant as that would be), but maintainability isn't something you can escape. That's my bet. Security also isn't something you can test your way out of. Tests show that the software *does* a thing, rather than that it *doesn't* do a thing. There are such things as security tests but they're usually written with specific implementations in mind, preventing certain kinds of easy mistakes from creeping into the codebase unnoticed. You can't take a set of security tests for one implementation and trust that they'll do anything for another one. (Many are also regression tests for a specific impl, written in retrospect...)
0
1
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Feb 08, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @varx@infosec.exchange
@nolan@toot.cafe The strongest steelman position I can make for the use of LLMs is that a senior developer can use them for fast feedback and maybe brainstorming. (As long as they're happy to accept a list of serious downsides and externalities.) When I see junior devs use them, the LLMs lead the dev down the garden path, creating more and more complicated workarounds where a senior dev would back up and take a fundamentally different approach. And when I see senior devs treat them as a team of junior devs that can independently produce a body of work, well... that's not a good way to work with actual junior devs! You have to carefully review their work, do mentoring, etc. There are somewhat analogous things you can do with agents but I don't have the sense that this is what people are really doing.
0
0
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Feb 08, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @varx@infosec.exchange
@nolan@toot.cafe A lot of my work has been in security. One of the things a lot of people don't appreciate is that security is largely about what "features" *don't* exist. For example, the feature that lets an attacker read your email. 😃 You have to try to prove that negative. This is important because a lot of people evaluate software by taking it for a test drive and seeing that the happy path works. But that can never work for security. The way you write secure software is by having a secure development process; by developing and communicating threat models; by recognizing dangerous patterns and guiding the software around that. LLMs are notoriously bad at all of this. I don't think this will be better in six months.
0
2
1
0
Open post
varx
varx/tech @varx@infosec.exchange · Feb 08, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @nolan@toot.cafe
@nolan@toot.cafe I read that post (I follow the RSS feed) but there's a really important point that you don't seem to cover: Is that code usable? It passes a lot of tests. Is it good enough to use in a real browser? (Functionality, performance, security.) Is it easy enough to work with that you could get it into good enough shape to use? Is it maintainable? *How do you know?*
0
1
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Feb 08, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @varx@infosec.exchange
@nolan@toot.cafe Importantly, this was also the situation a year ago, and a year ago people also said "just wait six months". And I did, and it's fundamentally the same situation. The agents can produce more code, larger projects. But that's actually worse because that's even harder to fix and maintain.
1
1
0
0
Open post
varx
varx/tech @varx@infosec.exchange · Feb 08, 2026
varx/tech
@varx@infosec.exchange

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm This is the more tech-y alt of https://cybersecurity.theater/@varx #nobot

infosec.exchange
Replying to @nolan@toot.cafe
@nolan@toot.cafe I can't speak to what I haven't seen, and I can't take people's word for this stuff because there's a *massive* amount of hype. Just endless waves of dubious benchmarks, demos that turn out to be fake or broken, reporting that isn't actually fact-based. So, I can only speak to what I've seen. And what I've seen ain't good.
0
15
0
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:06:26 UTC